Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Create and access a list of your products
  • Manage your Dell EMC sites, products, and product-level contacts using Company Administration.

How to Create a Secureworks Taegis XDR Agent Group

Summary: Learn about how to create an agent group in Secureworks Taegis XDR. Agent groups are used to associate endpoints to specific groups and assigned policies.

This article may have been automatically translated. If you have any feedback regarding its quality, please let us know using the form at the bottom of this page.

Article Content


Instructions

An administrator may create a Secureworks Taegis XDR agent group. This is used during installations to associate endpoints to specific group and assigned policy.


Affected Products:

  • Secureworks Taegis XDR
  • Secureworks Taegis ManagedXDR

Secureworks Taegis XDR agent groups are used to assign an endpoint to a policy during installation of the agent. Each group that is created is assigned a telemetry policy tier and registration key.

There are two tiers available. The two tiers impact the behavior, the amount of telemetry collected, and the level of performance impacted on the endpoint.

  • Low - A lower fidelity telemetry setting for resource-constrained devices or environments.
  • Standard - The recommended default policy setting.

Overview of telemetry gathered by policy tier:

Secureworks Taegis XDR Agent Telemetry Data Low Standard
Process Create Only Create, Terminate
Thread Injection Enabled Enabled
ETW (Auth, Scriptblock, DNS) Enabled Enabled
Netflow Connect1 Connect, Disconnect
Registry Disabled Modifications
File Open for mod, del, ren1 Open for mod, del, ren

1Netflow and File modification are disabled for Windows agents with a Low policy tier.

Note:
  • Only Process, Netflow, Auth, and FileMod are available for macOS and Linux.
  • For more information, reference the Telemetry Overview from Taegis Agent Technical DetailsThis hyperlink is taking you to a website outside of Dell Technologies..

An administrator may Create, Update, or Delete a Taegis agent group. Click the appropriate process for more information.

  1. In a web browser, go to https://ctpx.secureworks.com/loginThis hyperlink is taking you to a website outside of Dell Technologies..
  2. Log in to the Secureworks Taegis XDR web console.

Secureworks Taegis XDR login

  1. From the left pane, select Endpoints and then click Taegis.

Taegis Endpoints

  1. Select the Group Configuration tab.

Group Configuration tab

  1. Select the New Group button on the upper right.

New Group

  1. From the New Group menu:
    1. Populate the Name of Group.
    2. Populate the Description.
    3. Select a policy tier of Low or Standard.
    4. Click Create.

New Group menu

Updating the Taegis agent group allows you to rename the group and change the policy tier.

  1. In a web browser, go to https://ctpx.secureworks.com/loginThis hyperlink is taking you to a website outside of Dell Technologies..
  2. Log in to the Secureworks Taegis XDR web console.

Secureworks Taegis XDR login

  1. From the left pane, select Endpoints and then click Taegis.

Taegis Endpoints

  1. Select the Group Configuration tab.

Group Configuration tab

  1. Click an existing Group Name.

Existing Group Name

  1. From the Group Details menu, make any appropriate changes and then click Update.

Editing from the Group Details menu

  1. Verify that changes have been made.

Updated Group Name

  1. In a web browser, go to https://ctpx.secureworks.com/loginThis hyperlink is taking you to a website outside of Dell Technologies..
  2. Log in to the Secureworks Taegis XDR web console.

Secureworks Taegis XDR login

  1. From the left pane, select Endpoints and then click Taegis.

Taegis Endpoints

  1. Select the Group Configuration tab.

Group Configuration tab

  1. Click an existing Group Name.

Existing Group Name

  1. Select Delete Group in the lower right corner.

Delete Group

Note: If there are endpoints that are assigned to the group, then the group cannot be deleted. Reassign endpoints to a new group and then delete the Taegis Agent Group.

To contact support, reference Dell Data Security International Support Phone Numbers.
Go to TechDirect to generate a technical support request online.
For additional insights and resources, join the Dell Security Community Forum.

Article Properties


Affected Product

Secureworks

Last Published Date

11 Mar 2024

Version

4

Article Type

How To